Tenable Product Debug Data Collection Guide
This guide outlines the steps to collect diagnostic data for Tenable Support. When you open a case with Tenable Support, use this guide to generate a diagnostics file to attach to your support ticket.
Tenable diagnostics and debug logs are the primary tools for resolving complex issues across Tenable products. Administrators utilize these files to provide Tenable Support with a comprehensive snapshot of system health, configuration settings, and scan activities that are otherwise invisible in the user interface. These logs are crucial for investigating scan failures, performance bottlenecks, and authentication errors. By enabling "debug mode" for a targeted period, users capture data that helps engineers replicate local environments and identify the root cause of service disruptions, ensuring a more stable and accurate vulnerability management lifecycle.
The following are some use cases for opening a Tenable Support ticket with diagnostic and debug data:
-
Troubleshooting scan failures: Identifying why a scan hung, stopped prematurely, or failed to launch across specific segments.
-
Resolving Credential Failures: Analyzing exact handshake or permission errors when authenticated scans fail to access targeted assets.
-
Performance Optimization: Investigating high CPU or memory usage or database lag that impacts the speed of vulnerability processing.
-
Plugin Debugging: Verifying why specific plugins did not fire or why they produced suspected false positives or negatives on a host.
-
Upgrade & Installation Errors: Providing logs to resolve issues encountered during version migrations or initial setup failures.
-
Audit Trail Verification: Documenting unusual user activity or system changes for compliance and security forensics.
-
Connectivity & Sensor Health: Diagnosing communication breaks between the management console and remote Tenable Nessus scanners or Tenable Agents.
The steps for collecting data are divided into three phases. Not every Tenable product or issue requires all three phases. You may receive specific instructions to gather some or all of these:
Enable Plugin Debugging and Audit Trails
Use this section when troubleshooting false positives, authentication errors, or compliance checks. Apply these settings before running the scan.
Collect Scan Results
Use this section after the scan has finished. These files allow support to replay the scan results with full diagnostic data.
Collect System Debug Logs and Diagnostics Files
Use this section when troubleshooting software crashes, service failures, or installation errors.